Legal
Data Processing Agreement
This page is a summary of the Data Processing Agreement ("DPA") that WYSAMM LLC, trading as Adbustr (TIN 08222398, registered in the Republic of Armenia), enters into with partners where Adbustr processes personal data on their behalf. It is published for orientation only and is not the contract: it carries no annexes, no transfer mechanism and no signature block, and nothing on this page is executed by signing or referencing it.
To contract with us, request the executable DPA at compliance@adbustr.com. Tell us the contracting entity, its role (controller or processor), the jurisdictions involved and the integration you are onboarding, and we will send the document for review and signature together with the transfer paperwork described below.
1. Roles
- The Partner is the data controller
- Adbustr is the data processor for personal data processed on the Partner's instructions
- For our own analytics and platform-improvement processing, Adbustr acts as a controller
2. Scope and duration
Subject matter: programmatic ad exchange operations. Duration: the term of the underlying agreement plus statutory retention periods. The executable DPA sets out the categories of data subjects, categories of personal data and the processing operations in a dedicated annex.
3. Subprocessors
Authorized subprocessors:
- DigitalOcean (dedicated servers for exchange serving and logging — Amsterdam, European Union)
- OVH (dedicated servers for exchange serving and logging — Oregon, United States)
- Vercel (website and edge compute)
- Cloudflare (CDN / DDoS protection)
- Resend (transactional email)
- Plausible (privacy-preserving analytics)
Ad serving is therefore not confined to the EU/EEA. We provide partners 30 days' notice before adding or replacing subprocessors. Partners may object on reasonable grounds. The binding subprocessor list, with the processing location and processing purpose stated per entry, is issued as an annex to the executable DPA.
4. International transfers
Adbustr is established in the Republic of Armenia, which is not covered by an adequacy decision of the European Commission. Transfers of personal data from the EU/EEA to Adbustr therefore require an Article 46 transfer mechanism: the EU Standard Contractual Clauses, accompanied by a transfer impact assessment and the technical and organisational measures described in Section 5. The same applies to the United States leg of the serving infrastructure listed in Section 3. These mechanisms are issued as part of the executable DPA and are not established by this page.
5. Security measures
- Encryption in transit (TLS 1.2+)
- Encryption at rest for stored bid logs and PII
- Role-based access controls with least-privilege defaults
- Quarterly access review for production systems
- Incident response runbooks with 72-hour breach-notification commitment
6. Audit rights
Partners may request audit information or, with reasonable notice, conduct on-site audits no more than once per twelve months. Where an independent audit report covering the relevant controls is available, it will satisfy most audit requests.
7. Termination
Upon termination, Adbustr will return or delete personal data in accordance with the Partner's instructions and applicable retention requirements.
8. Requesting the executable DPA
Write to compliance@adbustr.com for the signable document, the Standard Contractual Clauses and the accompanying annexes. Data-protection questions unrelated to contracting go to dpo@adbustr.com.